Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

516 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.44%—Sysaid Help Desk11/9/202217/6/2026
SysAid Help Desk before 22.1.65 allows XSS, aka FR# 66542 and 65579.
ModificadaMedia (4.8)0.55%—Webhelpagency Word Search Puzzles9/9/202217/6/2026
Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in WHA's Word Search Puzzles game plugin <= 2.0.1 at WordPress.
ModificadaMedia (6.5)1.0%—Helpsystems Goanywhere Managed File Transfer27/7/202217/6/2026
A path traversal vulnerability exists within GoAnywhere MFT before 6.8.3 that utilize self-registration for the GoAnywhere Web Client. This vulnerability could potentially allow an external user who self-registers with a specific username and/or profile information to gain access to files at a higher directory level…
ModificadaCrítica (9.8)1.5%—Npm-help Project Npm-help25/7/202217/6/2026
This affects all versions of package npm-help. The injection point is located in line 13 in index.js file in export.latestVersion() function.
ModificadaMedia (6.1)0.70%—Adobe Robohelp15/7/202217/6/2026
Adobe RoboHelp versions 2020.0.7 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
ModificadaMedia (6.1)0.47%—Sync Oxygen Publishing EngineSync Oxygen XML AuthorSync Oxygen XML DeveloperSync Oxygen XML Editor+113/7/202217/6/2026
An issue was discovered in Oxygen XML WebHelp before 22.1 build 2021082006 and 23.x before 23.1 build 2021090310. An XSS vulnerability in search terms proposals (in online documentation generated using Oxygen XML WebHelp) allows attackers to execute JavaScript by convincing a user to type specific text in the WebHelp…
ModificadaAlta (7.5)1.1%—Scaffold-helper Project Scaffold-helper27/6/202217/6/2026
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in scaffold-helper v1.2.0 when copying crafted invalid files.
ModificadaAlta (8.8)1.5%—Adobe Robohelp Server16/6/202217/6/2026
RoboHelp Server earlier versions than RHS 11 Update 3 are affected by an Improper Authorization vulnerability which could lead to privilege escalation. An authenticated attacker could leverage this vulnerability to achieve full administrator privileges. Exploitation of this issue does not require user interaction.
ModificadaMedia (4.8)0.56%—Helpdeskz13/6/202217/6/2026
A cross-site scripting (XSS) vulnerability in /staff/setup/email-addresses of Helpdeskz v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email name field.
ModificadaMedia (4.8)0.56%—Helpdeskz13/6/202217/6/2026
A cross-site scripting (XSS) vulnerability in /staff/tools/custom-fields of Helpdeskz v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email name field.
ModificadaCrítica (9.8)1.7%—Pagehelper Project Pagehelper4/5/202217/6/2026
MyBatis PageHelper v1.x.x-v3.7.0 v4.0.0-v5.0.0,v5.1.0-v5.3.0 was discovered to contain a time-blind SQL injection vulnerability via the orderBy parameter.
ModificadaAlta (7.8)2.4%—Luya Yii-helpers1/5/202217/6/2026
Formula Injection/CSV Injection due to Improper Neutralization of Formula Elements in CSV File in GitHub repository luyadev/yii-helpers prior to 1.2.1. Successful exploitation can lead to impacts such as client-sided command injection, code execution, or remote ex-filtration of contained confidential data.
ModificadaMedia (6.1)0.65%—Livehelperchat Live Helper Chat29/4/202217/6/2026
Cross-site Scripting (XSS) in GitHub repository livehelperchat/livehelperchat prior to 3.99v. The attacker can execute malicious JavaScript on the application.
ModificadaMedia (6.5)0.46%—Motorola Device HelpMotorola Ready FOR22/4/202217/6/2026
Versions of Motorola Ready For and Motorola Device Help Android applications prior to 2021-04-08 do not properly verify the server certificate which could lead to the communication channel being accessible by an attacker.
ModificadaMedia (5.5)0.29%—Helpsystems Titus Data Classification21/4/202217/6/2026
The Labeling tool in Titus Classification Suite 18.8.1910.140 allows users to avoid the generation of a classification label by using Excel's safe mode.
ModificadaAlta (8.8)1.3%—Livehelperchat Live Helper Chat7/4/202217/6/2026
Host Header injection in password Reset in GitHub repository livehelperchat/livehelperchat prior to 3.97.
ModificadaMedia (6.1)0.73%—Livehelperchat Live Helper Chat6/4/202217/6/2026
XSS in livehelperchat in GitHub repository livehelperchat/livehelperchat prior to 3.97. This vulnerability has the potential to deface websites, result in compromised user accounts, and can run malicious code on web pages, which can lead to a compromise of the user’s device.
ModificadaAlta (8.2)0.56%—Livehelperchat Live Helper Chat5/4/202217/6/2026
Weak secrethash can be brute-forced in GitHub repository livehelperchat/livehelperchat prior to 3.96.
ModificadaAlta (8.1)0.58%—Livehelperchat Live Helper Chat5/4/202217/6/2026
SSRF filter bypass port 80, 433 in GitHub repository livehelperchat/livehelperchat prior to 3.67v. An attacker could make the application perform arbitrary requests, bypass CVE-2022-1191
ModificadaAlta (7.5)1.3%—Livehelperchat Live Helper Chat31/3/202217/6/2026
Loose comparison causes IDOR on multiple endpoints in GitHub repository livehelperchat/livehelperchat prior to 3.96.
ModificadaAlta (8.1)0.95%—Livehelperchat Live Helper Chat31/3/202217/6/2026
SSRF on index.php/cobrowse/proxycss/ in GitHub repository livehelperchat/livehelperchat prior to 3.96.
ModificadaAlta (8.8)1.0%—Solarwinds Webhelpdesk25/3/202217/6/2026
SolarWinds received a report of a vulnerability related to an input that was not sanitized in WebHelpDesk. SolarWinds has removed this input field to prevent the misuse of this input in the future.
ModificadaMedia (4.3)0.74%—Jenkins Release Helper15/3/202217/6/2026
A missing permission check in Jenkins Release Helper Plugin 1.3.3 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.
ModificadaMedia (4.3)0.49%—Jenkins Release Helper15/3/202217/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Release Helper Plugin 1.3.3 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials.
ModificadaMedia (5.3)0.95%—Solarwinds WEB Help Desk10/3/202217/6/2026
Sensitive information could be displayed when a detailed technical error message is posted. This information could disclose environmental details about the Web Help Desk installation.